Authenticated Remote Code Execution in Nginx Proxy Manager by Nginx
CVE-2026-40519

7.7HIGH

Key Information:

Vendor
CVE Published:
8 June 2026

What is CVE-2026-40519?

Nginx Proxy Manager versions 2.9.14 through 2.15.1 are susceptible to an authenticated remote code execution vulnerability due to improper handling of user inputs. Specifically, the vulnerability is triggered via the dns_provider_credentials field during the execution of the setupCertbotPlugins() function. Attackers possessing 'certificates:manage' permissions can exploit this flaw by injecting malicious code that gets executed without proper validation or escaping, leading to arbitrary command execution when the backend is restarted.

Affected Version(s)

nginx-proxy-manager 2.9.14 <= 2.15.1

nginx-proxy-manager 2.9.14 <= 2.15.1

nginx-proxy-manager a5db5ed156355e3088e7d1ceb0533d4bae922def

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yassine Damiri
.